Job Title : IT Security Analyst
Location : Richmond, VA
Contract Duration : 6 Months
Complete Description :
The IT Security Analyst will play a critical role in supporting cybersecurity efforts within the Tolling Division's systems, ensuring the safety and integrity of tolling infrastructure. The successful candidate will monitor security alerts, analyze potential security incidents, and contribute to incident response efforts. This role will require close coordination with multiple teams to implement cybersecurity best practices and ensure compliance with established security frameworks such as NIST and PCI DSS.
Key Responsibilities :
- Security Monitoring : Monitor security alerts and logs for tolling-related infrastructure using existing SIEM and other monitoring tools.
- Incident Analysis : Analyze, investigate, and triage security events and potential incidents involving tolling back-office systems and devices.
- Incident Response : Coordinate with Tolling Division personnel, vendors, and OT operations teams to facilitate incident response, forensics, and remediation activities.
- Onboarding Systems : Assist in onboarding tolling systems into the OT cybersecurity monitoring process, including asset inventory, log ingestion, and configuration baselines.
- Security Assessments : Perform security assessments and reviews of tolling systems for vulnerabilities, misconfigurations, and compliance with NIST 800-53, NIST 800-82, and other agency-specific policies.
- Incident Response Playbooks : Participate in the development and maintenance of incident response procedures and playbooks specific to tolling infrastructure.
- Security Reporting : Contribute to regular security reporting, dashboards, and metrics for tolling systems.
- Stakeholder Collaboration : Collaborate with internal and external stakeholders to enhance the security posture of the tolling environment.
Qualifications : Required :
Bachelor's degree in Cybersecurity, Information Technology, Engineering, or a related field; OR equivalent experience.3+ years of experience in cybersecurity, with at least 1 year supporting Azure, IIS, Active Directory, SQL databases, and critical infrastructure environments.Familiarity with SIEM tools, log analysis, and incident response workflows.Familiarity with PCI DSS security requirements.Working knowledge of networking protocols, system hardening, and asset inventory practices.Strong analytical, communication, and collaboration skills.Preferred :
Experience supporting or securing tolling systems, traffic management infrastructure, or roadside equipment.Knowledge of security frameworks such as PCI DSS, NIST 800-53, NIST 800-82, or CIS Controls.Certifications such as GICSP, GCIA, CompTIA Security+, or CISSP.Experience working with third-party vendors and supporting environments with both state-managed and vendor-managed components.